GlossaryAttack surface and pentesting

Pentesting

Short answer

Pentesting (penetration testing) is an authorised, simulated attack on systems, applications or networks, carried out by security specialists to find vulnerabilities that a real attacker could exploit. The result is a report with each finding, its risk and how to fix it.

Types of pentest

Pentests are defined by what is tested: external infrastructure exposed to the internet, the internal network, web applications, APIs, mobile apps or cloud environments. They are also defined by how much information the testers receive in advance: black box (none), grey box (some, such as user credentials) or white box (full access to documentation and code).

Pentesting vs vulnerability scanning

A vulnerability scan is automated and lists known weaknesses. A pentest is carried out by people who confirm which weaknesses can actually be exploited, chain them together and show the real impact. Both are useful, and they answer different questions.

What a good report includes

A pentest report describes each finding, its severity, how it was exploited and how to fix it, with priorities based on real risk. A retest confirms that the fixes worked.

Where it shows up in compliance

Regular technical testing is expected under ISO 27001, the ENS, NIS2 and SOC 2. DORA requires resilience testing and, for some financial entities, threat led penetration testing (TLPT).

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub